CVE-2020-24917: Enhancesoft Osticket

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.

Affected products

Published 2020-08-30. Last modified 2026-07-10.